~wgrant/ubuntu-cve-tracker/mainold

« back to all changes in this revision

Viewing changes to active/CVE-2008-1382

  • Committer: William Grant
  • Date: 2008-04-19 08:08:17 UTC
  • mfrom: (1065.2.58 ubuntu-cve)
  • Revision ID: william@qeuni.net-20080419080817-274tzbq5c88enccc
MergeĀ fromĀ master.

Show diffs side-by-side

added added

removed removed

Lines of Context:
 
1
Candidate: CVE-2008-1382
 
2
References:
 
3
 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1382
 
4
Description:
 
5
 libpng 1.0.6 through 1.0.32, 1.2.0 through 1.2.26, and 1.4.0beta01 through
 
6
 1.4.0beta19 allows context-dependent attackers to cause a denial of service
 
7
 (crash) and possibly execute arbitrary code via a PNG file with zero length
 
8
 "unknown" chunks, which trigger an access of uninitialized memory.
 
9
Ubuntu-Description:
 
10
Notes:
 
11
Bugs:
 
12
Priority: low
 
13
Discovered-by: Tavis Ormandy
 
14
Assigned-to:
 
15
 
 
16
Patches_libpng:
 
17
upstream_libpng: released (1.2.27)
 
18
dapper_libpng: needed
 
19
edgy_libpng: needed
 
20
feisty_libpng: needed
 
21
gutsy_libpng: needed
 
22
devel_libpng: needed